PT-2006-4617 · Zen Cart · Zen Cart
O Y
·
Published
2006-07-21
·
Updated
2018-10-17
·
CVE-2006-3757
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zen Cart version 1.3.0.2
Description
The issue allows remote attackers to obtain sensitive information via empty array parameters, which reveals the installation path in an error message. This is achieved by manipulating the
GET[], SESSION[], POST[], or COOKIE[] arrays.Recommendations
For Zen Cart version 1.3.0.2, consider restricting access to the index.php file until a patch is available, or apply configuration changes to prevent the exposure of sensitive information through error messages.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zen Cart